-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dolibarr/dolibarr | composer | < 19.0.2 | 19.0.2 |
The analysis focused on the changes made to htdocs/compta/paiement/card.php, where the handling of the 'facid' parameter was modified to use GETPOSTINT, indicating a previous vulnerability due to direct use of $_GET['facid']. The formconfirm() function is identified as vulnerable due to its use of $facid in generating output.
A Semantic Attack on Google Gemini - Read the Latest Research